> TODAY'S SUMMARY (55 articles)
Today's cybersecurity landscape highlights significant threats and vulnerabilities that organizations must address. Forescout warns that inadequate network segmentation is enlarging attack surfaces, making businesses more vulnerable. A critical vulnerability in ZyXEL switches has been exploited by Chinese hackers, leading to the exfiltration of sensitive data from nearly 1,000 devices globally. Additionally, a newly discovered flaw in the Linux kernel allows unauthorized access to host memory from guest virtual machines, raising concerns for cloud environments. Meanwhile, a malicious NPM package, disguised as a legitimate software, has garnered millions of downloads, highlighting the persistent threat of supply chain attacks. Lastly, CISOs are urged to update incident response playbooks in light of emerging AI-driven threats, including sophisticated deepfakes and autonomous malware.
|
// AI-powered summary generated at 12:01
Shasta County registrar Clint Curtis told CyberScoop he needs Peters to help manage the county’s 2026 elections and he’s not concerned about her past conviction.
The post Election official says Tina Peters would be consultant, won’t have access to election systems appeared first on CyberScoop.
Interpol operation leads to 58 arrests and identifies 263 suspects across 22 countries
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. [...]
Chrome’s latest update fixes 327 security vulnerabilities, including some that malicious websites could exploit as soon as you visit them.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes.
B...
Reco report reveals growing shadow AI problem and surge in vulnerability disclosures
A new joint study by Tenable and SentinelOne reveals how state and criminal groups converge on the same vulnerable edge infrastructure.
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of...
Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.
The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
Learn how to scan a document on iPhone using Notes, Files, Preview, and Proton Drive. Only one of these protects your privacy by default.
A Utah investigation found educational apps collecting unauthorized student data and sharing information with third parties and advertisers.
Microsoft has begun testing new privacy controls that will let Windows 11 users choose which desktop applications can access their camera, microphone, and precise location. [...]
The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI.
Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recent...
Chubb reported that growing privacy litigation has contributed to surging cyber claim costs in the US
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it.
The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem f...
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then...
A vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine.
According to a Cyera research, the flaw could give attackers unauthenticated access to the serve...
The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.
The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek.
Microsoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to adopt network-level controls to limit exposure during that...
Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]